Amendments to the Claims; 

This listing of claims will replace all prior versions, and listings, of claims in the application: 

Listing of Claims; 

1 . (Original) A method of logging audit events in a data processing system, the method comprising 
the computer implemented steps of: 

writing a sequence of audit records including a final audit record to a first log file stored by a data 
processing system; 

calculating a respective first hash value of each audit record; 

responsive to calculating each respective first hash value, calculating a corresponding second 
hash value from the first hash value and a value of a register associated with the data processing system; 
writing the second hash value to the register; 
responsive to closing the first log file, opening a second log file; and 

writing, to a first record of the second log file, a final second hash value corresponding to a first 
hash value of the final audit record. 

2. (Original) The method of claim 1, fiirther comprising: 

generating a cryptographically signed value of the final second hash value; and 
writing the signed value to the first record of the second log file. 

3. (Original) The method of claim 2, wherein the signed value is generated using an identity of a 
trusted platform module of the data processing system. 

4. (Original) The method of claim 1, wherein each respective first hash value and corresponding 
second hash value are calculated from a US secure hashing algorithm- 1. 

5. (Original) The method of claim 1, wherein writing the second hash value further comprises: 
performing an extend function, wherein the first hash value is included as an operand of an 

extend function call and the register is a platform configuration register. 

6. (Original) The method of claim 1, wherein calculating a corresponding second hash further 
comprises: 

concatenating the register value with the first hash value; and 
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calculating the second hash value from a result of concatenating the register value with the first 
hash value. 

7. (Currently Amended) A method for verifying a source of a log file, the method comprising the 
computer implemented steps of: 

iteratively calculating a respective first hash value of a plurality of records of a first log file; 

responsive to calculating the respective first hash value, calculating a corresponding second hash 
value from the first hash value and a second value , wherein the second value is a stored value of a register 
parsed from a previous record : 

responsive to calculating each second hash value, storing the second hash value as the second 

value; 

responsive to calculating a first hash value and a corresponding second hash value for a final 
record of the plurality of records, comparing the second hash value of the final record to a value stored in 
a record of a second log file ; and 

responsive to a determination that the second hash value of the final record of the first log file 
matches the value stored in the record of the second log file, validating the authenticity of the first log 
file. 

8. (Original) The method of claim 7, wherein iteratively calculating further comprises: 
calculating an initial first hash value, wherein the second value is a stored value of a register read 

when the first log file is created. 

9. (Original) The method of claim 7, further comprising: 

reading a first record of the first log file, wherein the first record includes an initial value of the 
second value. 

10. (Original) A computer program product in a computer readable medium for recording audit 
events, the computer program product comprising: 

first instructions for writing a first sequence of records to a first log file and for writing a second 
sequence of records to a second log file, wherein the records of the first sequence include a final record; 

second instructions for calculating a respective first hash value of each record of the first 
sequence; 
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third instructions for calculating a second hash value from the first hash value of the final reconl, 
wherein the second hash value is calculated fi-om a hash of the first hash value of the final record and a 
value of a register; and 

fourth instructions for writing the second hash value of the final record to a record of the second 

log file. 

1 1 . (Original) The computer program product of claim 1 0, wherein the first instructions open the 
second log file upon closing the first log file. 

12. (Original) The computer program product of claim 1 1, wherein the third instructions read the 
value of the register when the first log file is closed. 

1 3 . (Original) The computer program product of claim 10, wherein the fourth instructions write a 
cryptographically signed value of the value of the register to the record of the second log file. 

14. (Original) The computer program product of claim 10, wherein the third instructions calculated a 
respective second hash value for each first hash value. 

15. (Original) The computer program product of claim 14, wherein the third instructions write the 
second hash value to the register upon calculating the respective second hash value for each first hash 
value. 

1 6. (Original) A data processing system for recording audit events, comprising: 

a memory that contains a first audit log file and an auditing application as a set of instructions; 
a trusted platform module having a platform configuration register; and 

a processing unit, responsive to execution of the set of instructions, for calculating a hash value of 
an audit record written to the first audit log file and that extends a value of the platform configuration 
register with the hash value, wherein the processing unit, responsive to closing the first log file, identifies 
a final value of the platform configuration register and writes the final value to a second audit log file. 

1 7. (Original) The data processing system of claim 16, wherein the final value is derived from a hash 
value calculated from a final audit record written to the first audit log file and a value of the platform 
configuration register identified after writing the final audit record. 
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18. (Original) The data processing system of claim 16, wherein the processing unit calculates a 
signature of the final value and writes the signature to the second audit log file. 

1 9. (Original) The data processing system of claim 16, wherein the signature is generated from an 
attestation identity key of the trusted platform module. 

20. (Original) The data processing system of claim 1 6, wherein the processing unit writes a final 
audit record to the first audit log file and an audit record generated subsequent to the final audit record to 
the second audit log file. 
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